Trojan

Should I remove “Trojan:Win32/Amadey.PAD!MTB”?

Malware Removal

The Trojan:Win32/Amadey.PAD!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Amadey.PAD!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the RedLine malware family
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Amadey.PAD!MTB?


File Info:

name: 3C6C46B8038D6BC3E200.mlw
path: /opt/CAPEv2/storage/binaries/523f16eb5ae159afbd6b92c90a6d7e51dead57029130b785478cfe5f63ac69b3
crc32: 9B9B1201
md5: 3c6c46b8038d6bc3e200fbcb87e152d1
sha1: a48ed20e999ae2e49e3732a55d087eb98464d8dc
sha256: 523f16eb5ae159afbd6b92c90a6d7e51dead57029130b785478cfe5f63ac69b3
sha512: f7c329d3174bec5e5629d4476c4c6552b008280be281fea1f4254d6a5e38b3779528bfc41653d94e3e45357b0fc77cbac3b8556789a8bdc0f78676aaf8098ab2
ssdeep: 6144:fmnIvepkCaCGj0837BHvU3K/m2QtueV8lPjgP7MKfsYHCzT:OIvItaC000BHwKu2Qr85gjxsKm
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CC74F1617BD1D073C80687349410C6FCA97EB866958A85D773287FAF2E7138267BE260
sha3_384: 219231c20cf7dc16364e0607d45b83052f0c6c00ad6f8640aac51f51ab2747aa4300f45108afe8ccf994d6c3197cae03
ep_bytes: e8d62c0000e978feffff8bff558bec8b
timestamp: 2022-06-29 23:22:38

Version Info:

FilesVersion: 21.21.28.6
InternalName: DogmaticSuffering
OriginalFilename: nsadgiuubsdig.exe
ProductsVersion: 80.23.73.2
ProductName: Doppelgamer
ProductionVersion: 1.0.0.3
Translation: 0x01fd 0x23b0

Trojan:Win32/Amadey.PAD!MTB also known as:

BkavW32.AIDetect.malware1
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Zusy.463152
ClamAVWin.Packer.pkr_ce1a-9980177-0
FireEyeGeneric.mg.3c6c46b8038d6bc3
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWRiskware ( 0040eff71 )
K7AntiVirusTrojan ( 0056dffa1 )
CyrenW32/Kryptik.JQY.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HTKS
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Spy.Win32.Stealer.gen
BitDefenderGen:Variant.Zusy.463152
AvastWin32:CrypterX-gen [Trj]
SophosMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Lockbit.fc
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.Zusy.463152 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Zusy.463152
AviraTR/Spy.Stealer.jfgjm
Antiy-AVLTrojan/Win32.Sabsik
ArcabitTrojan.Mikey.D23CEB
ZoneAlarmHEUR:Trojan-Spy.Win32.Stealer.gen
MicrosoftTrojan:Win32/Amadey.PAD!MTB
GoogleDetected
AhnLab-V3Trojan/Win.Amadey.R575353
Acronissuspicious
McAfeeArtemis!3C6C46B8038D
MAXmalware (ai score=81)
VBA32Trojan.Buzus
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002H01DQ23
RisingTrojan.Kryptik!1.E4D1 (CLASSIC)
IkarusTrojan.Win32.SmokeLoader
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.JRS!tr
AVGWin32:CrypterX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Amadey.PAD!MTB?

Trojan:Win32/Amadey.PAD!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment